Auth Source แบบ Certificate ให้ผู้ใช้ยืนยันตัวตนด้วย Personal Certificate ที่ติดตั้งบนเครื่อง แทนการกรอกรหัสผ่าน เหมาะกับองค์กรที่มีระบบ PKI (Certificate Authority) อยู่แล้ว ผู้ดูแลระบบอัปโหลด Root Certificate ของ CA ไว้ใน Auth Source แล้วออก Personal Certificate ที่ลงนามโดย CA นี้ให้ผู้ใช้แต่ละคน ระบบจับคู่ค่าใน Certificate (เช่น CN) กับ Username ของผู้ใช้ บทความนี้อธิบายการเตรียม Certificate การเพิ่ม Auth Source การเปิดใช้ใน Authentication Policy และการ Login ของผู้ใช้
สารบัญ
สิ่งที่ต้องเตรียม
- Root Certificate ของ CA ที่ใช้ออก Personal Certificate เป็นไฟล์ CRT, CER หรือ P7B ขนาดไม่เกิน 5 MB
- Personal Certificate ของผู้ใช้แต่ละคนที่ลงนามโดย CA นี้ และติดตั้งไว้บนเครื่องของผู้ใช้
- ค่าใน Certificate ที่จะใช้จับคู่กับผู้ใช้ เช่น CN ต้องตรงกับ Username ของผู้ใช้ใน User Management
เพิ่ม Auth Source แบบ Certificate
- ไปที่ Platform Management › Identity Management › Authentication Policies แท็บ Mobile Users แล้วกด Manage Auth Sources
- กด Add Auth Source แล้วกด Certificate หน้าต่าง Details จะเปิดขึ้น (การคลิกไอคอนประเภทจะสร้าง Auth Source ให้ทันที จึงควรคลิกเมื่อพร้อมตั้งค่าจริง)
- ที่ Certificate Settings กด Add Certificate
- หน้าต่าง Add CA Certificate กรอก Name เลือกไฟล์ Root Certificate ที่ช่อง File แล้วกด OK
- ตรวจ Directory Settings โดยทั่วไปแนะนำให้ใช้ค่าในฟอร์ม
ฟิลด์ คำอธิบาย Associated Directory * Directory ที่ผูกกับ Auth Source นี้ ในฟอร์มเลือกไว้ที่ /Certificate Encoding * เลือกรูปแบบ Encoding ให้ตรงกับ Certificate ขององค์กร Mapping Rules * จับคู่ Certificate Field กับ Local Attribute ค่าในฟอร์มคือ CN → Username - ส่วน Advanced มีตัวเลือก Enable realtime user verification เปิดใช้ตามนโยบายขององค์กร
- กด OK แล้วกด Enable ที่มุมขวาบนของหน้าต่าง Details
เปิดใช้ใน Authentication Policy
- ที่หน้า Authentication Policies › Mobile Users › PC (Client Access) กด Edit ที่มุมซ้ายล่าง
- ที่ Auth Method ติ๊ก Tile Certificate (วิธีอื่นที่เลือกไว้ยังคงใช้ได้ ผู้ใช้เลือกได้ที่หน้า Login)
- กด Save
Certificate Redirect ใน Authentication Settings › Custom Authentication Page เลือกได้ว่าเมื่อ Login ด้วย Certificate จะให้ Login อัตโนมัติ (Auto login) หรือให้ผู้ใช้กดปุ่มก่อน (Redirect with button clicks) ดู Custom Authentication Page
การ Login ของผู้ใช้
- ตรวจว่าเครื่องของผู้ใช้ติดตั้ง Personal Certificate ที่ลงนามโดย Root Certificate ที่อัปโหลดไว้แล้ว
- ผู้ใช้กด Log In บน Omnipoint Secure Client ถ้าหน้า Login แสดงวิธีอื่นก่อน ให้เลือก Certificate ใต้ More Login Options
- หน้า Certificate Authentication กด Log In Browser จะแสดงหน้าต่างให้เลือก Certificate
- เลือก Personal Certificate ของตนเอง แล้วกด OK เพื่อเข้าสู่ระบบ
ที่ Console ตรวจผลได้ที่ Dashboard › User Status และ Logs › User Access › Login/Logout แท็บ Client Users
ข้อแนะนำและปัญหาที่พบบ่อย
| อาการหรือเรื่องที่ควรรู้ | สิ่งที่ควรทำ |
|---|---|
| Browser ไม่แสดง Certificate ให้เลือก | ตรวจว่า Personal Certificate ติดตั้งในเครื่องของผู้ใช้แล้ว และลงนามโดย CA เดียวกับ Root Certificate ที่อัปโหลดไว้ |
| เลือก Certificate แล้วเข้าระบบไม่ได้ | ตรวจว่าค่า CN (หรือ Field ที่ตั้งใน Mapping Rules) ตรงกับ Username ของผู้ใช้ใน User Management และ Certificate ยังไม่หมดอายุ |
| อัปโหลด Root Certificate ไม่ได้ | ใช้ไฟล์ CRT, CER หรือ P7B ขนาดไม่เกิน 5 MB |
| วางแผนการใช้งานระยะยาว | ออก Personal Certificate ใหม่ให้ผู้ใช้ก่อนหมดอายุ และเปิดวิธี Login อื่นไว้สำรอง เช่น Password หรือ Microsoft AD ใต้ More Login Options |
ข้อคิดเห็น
0 ข้อคิดเห็น
โปรด ลงชื่อเข้าใช้ เพื่อแสดงข้อคิดเห็น